Background
Data Governance

Data Retention Policy

This policy describes how long Chargezen retains different categories of data and the processes for secure deletion when retention periods expire.

Effective: January 4, 2026Updated Annually

Policy Overview

Chargezen is committed to retaining personal data only for as long as necessary to fulfill the purposes for which it was collected, while complying with legal, regulatory, and business requirements.

This Data Retention Policy establishes standardized retention periods for all categories of data processed by Chargezen, ensuring:

  • Legal Compliance: Meeting requirements under GDPR, CCPA, TCPA, and other regulations
  • Business Needs: Supporting operations, analytics, and customer service
  • Data Minimization: Retaining only what is necessary for stated purposes
  • Security: Reducing risk by limiting the data we store

Retention Schedule

The following table details retention periods for each category of data we process.

Account Information

Duration of account + 3 years

Data Types

Name, email, phone, company name, login credentials

Rationale

Legal obligations, dispute resolution, re-activation support

Deletion Method

Upon verified deletion request or automatic after retention period

Transaction Records

7 years from transaction date

Data Types

Order history, payment records, invoices, subscription history

Rationale

Tax compliance, financial audits, legal requirements (IRS, state laws)

Deletion Method

Automatic deletion after retention period

Customer Communications

3 years from last interaction

Data Types

Support tickets, emails, chat logs, call recordings

Rationale

Service improvement, dispute resolution, quality assurance

Deletion Method

Automatic deletion after retention period

SMS/Voice Records (SmartyTap)

Consent records: 5 years | Message logs: 2 years

Data Types

Message content, delivery status, opt-in/opt-out records, consent timestamps

Rationale

TCPA compliance, regulatory audits, legal defense

Deletion Method

Consent records retained for regulatory compliance; message content deleted on schedule

Affiliate Data (Spark!)

Duration of relationship + 5 years

Data Types

Affiliate profiles, commission records, referral tracking, payout history

Rationale

Tax reporting (1099), commission disputes, fraud prevention

Deletion Method

Upon program termination + retention period

Analytics & Usage Data

2 years

Data Types

Page views, feature usage, click events, session data

Rationale

Product improvement, trend analysis, performance optimization

Deletion Method

Aggregated/anonymized after 90 days; fully deleted after 2 years

Security Logs

1 year (standard) | 3 years (security incidents)

Data Types

Login attempts, IP addresses, access logs, audit trails

Rationale

Security monitoring, incident investigation, compliance

Deletion Method

Automatic deletion after retention period

Marketing Data

Until consent withdrawn + 1 year

Data Types

Email campaign interactions, ad engagement, preferences

Rationale

Marketing attribution, preference management, legal compliance

Deletion Method

Upon opt-out + retention period for compliance records

Cookies & Tracking

Session cookies: Session end | Persistent: Up to 13 months

Data Types

Cookie identifiers, device fingerprints, tracking pixels

Rationale

Session management, analytics, personalization

Deletion Method

Session cookies deleted on browser close; others on schedule

Backup Data

90 days

Data Types

All data categories in backup systems

Rationale

Disaster recovery, business continuity

Deletion Method

Rolling deletion as new backups replace old

Deletion Methods

We employ multiple secure methods to delete data depending on the data type and regulatory requirements.

Hard Deletion

Complete and irreversible removal of data from all systems

Applies To:

Data past retention period, verified deletion requests

Timeframe:

30 days from trigger

Soft Deletion

Data marked as deleted but retained in backup for recovery period

Applies To:

Account closures, initial deletion requests

Timeframe:

90-day recovery window before hard deletion

Anonymization

Irreversible removal of identifying information while retaining aggregate data

Applies To:

Analytics data, usage statistics for product improvement

Timeframe:

Per retention schedule

Encryption Key Destruction

Destroying encryption keys rendering encrypted data unreadable

Applies To:

Highly sensitive data, cryptographic deletion

Timeframe:

Immediate upon deletion trigger

Legal Bases for Retention

1

Legal Obligation

Tax records, financial reporting, regulatory compliance

Examples: IRS requirements (7 years), TCPA consent records (5 years)

2

Legitimate Interest

Business operations, security, fraud prevention

Examples: Security logs, fraud detection data

3

Contractual Necessity

Required to fulfill services under agreement

Examples: Account data, service configuration

4

Consent

Data processed based on user consent

Examples: Marketing communications, optional analytics

Exceptions to Standard Retention

Data may be retained beyond standard periods in the following circumstances:

  • Active Litigation: Data relevant to pending or reasonably anticipated litigation
  • Regulatory Investigation: Data subject to ongoing regulatory inquiry
  • Legal Hold: Data subject to preservation orders
  • Contractual Obligations: Specific retention requirements in customer agreements

Your Data Rights

You have the right to request deletion of your personal data before the end of standard retention periods. To exercise this right:

Questions About Data Retention?

Our privacy team can help you understand how your data is stored and provide information about exercising your data rights.

Space, at your fingertips

What would you do with 22% more revenue?